Advertise on KripZen — put your brand in front of a global crypto audience.Get in touch →

Glossary entry

Evil Maid Attack

Wallets & Security

Tampering with a device left unattended, why buying from the manufacturer does not cover it, and the one prompt that should stop an owner immediately.

Definition

An evil maid attack is tampering with an unattended device so that it betrays its owner the next time it is used — the name comes from the scenario of a hotel room cleaned while the guest is out. In crypto the target is whatever sits between the owner and a signature: a laptop that can be given a modified boot process or a keylogger, a phone left in a drawer, or a hardware wallet swapped for a lookalike so the owner enters a PIN or a recovery phrase into an attacker's device. It is the reason the ordinary advice about buying only from the manufacturer does not finish the job, because that advice covers the device's arrival and says nothing about the years afterwards. The defences are physical and procedural rather than cryptographic: keep signing devices where their absence would be noticed, use tamper-evident storage so a device that was opened looks it, treat a device that left your control as suspect, and remember that a wallet asking for a recovery phrase where it never has before is the signal, not a glitch.

Next

Related terms

More in Wallets & Security